Why this matters now

DPDP is the most-debated current law in tech governance. Tested for: the Srikrishna Committee origins, the deemed-consent doctrine, Data Protection Board, age of consent (18), Significant Data Fiduciary classification, penalties up to Rs 250 crore, cross-border data transfer regime, and the exemption for State agencies on national security grounds.

11 Aug 2023
Notified
Puttaswamy 2017
Trigger
Rs 250 crore
Max penalty
Data Protection Board
Statutory body

Genesis: Srikrishna Committee → 5 drafts → 2023 Act

Puttaswamy (2017) directed the Government to frame a privacy law. The Justice B.N. Srikrishna Committee (chaired by former SC Judge B.N. Srikrishna; constituted July 2017) submitted its report and draft Personal Data Protection Bill in July 2018. The Bill went through five drafts (2018, 2019, 2021 JPC, 2022 withdrawn, 2023) — finally passed Parliament in August 2023.

Key provisions

ConceptProvision
Data PrincipalThe person whose data is being processed (individual citizen).
Data FiduciaryEntity that determines the purpose & means of processing data. Subject to obligations.
Significant Data FiduciaryDesignated by Government based on volume & sensitivity; subject to additional obligations (impact assessment, audit).
ConsentNotice in clear language; free, specific, informed, unambiguous. Can be withdrawn.
ChildrenUnder 18 cannot consent; verifiable parental consent required.
Data Principal rightsRight to information about processing, right to correction & erasure, right to grievance redressal, right to nominate.
Data Protection Board of IndiaStatutory body; adjudicates breaches; appellate jurisdiction to TDSAT.
PenaltiesUp to Rs 250 crore per breach (e.g., for failing to prevent personal data breach).
Cross-border transferPermitted EXCEPT to countries notified in negative list (vs the 2022 Bill’s whitelist approach). Centre may restrict by notification.
State exemptionGovernment may exempt its own instrumentalities from any DPDP provision “in the interest of sovereignty, integrity, security of State, public order, defence, etc.” (§ 17). Controversial.

Comparison with EU GDPR

AspectEU GDPR (2018)DPDP 2023
Sensitive dataSpecial category (health, religion, ethnicity)NO separate category — criticised
Data localisationGenerally free flow with safeguardsFree with notified negative list
Right to be forgottenExplicit (Art 17)Implicit (correction & erasure)
State exemptionLimited; must be proportionateBroad (§ 17) — criticised
Max penalty4% global turnover or €20 mRs 250 crore
Age of consent16 (member states can lower to 13)18 with verifiable parental consent

UPSC angle

Know DPDP Act 2023 — notified 11 Aug 2023; operationalises Puttaswamy 2017; Srikrishna Committee 2018 first draft, 5 drafts total (2018/2019/2021 JPC/2022 withdrawn/2023); Data Principal = individual citizen, Data Fiduciary = entity processing, Significant Data Fiduciary = high volume/sensitivity; consent must be free/specific/informed; under-18 requires verifiable parental consent; rights to info/correction/erasure/nomination; DATA PROTECTION BOARD OF INDIA statutory body (appeal to TDSAT); penalties up to Rs 250 crore; cross-border transfer permitted except notified negative list; §17 STATE EXEMPTION on sovereignty/security grounds (controversial vs GDPR).

Frequently asked questions

When was DPDP Act notified?

11 August 2023.

Who is a Data Fiduciary?

An entity that determines the purpose and means of processing personal data — subject to obligations under DPDP.

What is the maximum penalty under DPDP?

Up to Rs 250 crore per breach (e.g., for failing to take reasonable security measures).

Does DPDP have a separate sensitive-data category?

No — unlike GDPR, DPDP does not separately categorise sensitive personal data (health, religion, etc.) — a criticism of the law.